Exercise

Fix SELinux Label on about.html File Exercise

Task

Give about.html the label the policy expects, confirm Apache serves it, and see what a copy would have done differently.

Host
workstation
Prerequisite
Add New Web Page Exercise
  1. Inspect the policy for /var/www

    sudo semanage fcontext -l | grep '/var/www' | head -n5
  2. Apply the policy to /var/www recursively

    sudo restorecon -Rv /var/www
    ls -lZ /var/www/html/

    restorecon reports each file it relabels. about.html changes from user_tmp_t to httpd_sys_content_t.

  3. Verify access to about.html

    getenforce
    curl http://localhost/about.html

    With SELinux enforcing, you should see <h1>About Us</h1>.

  4. Test cp vs mv

    What if the page had been copied instead of moved?

    echo '<h1>About Us - Again</h1>' > /tmp/about2.html
    ls -lZ /tmp/about2.html
    sudo cp /tmp/about2.html /var/www/html/about2.html
    ls -lZ /var/www/html/about2.html
    curl http://localhost/about2.html
  5. Clean up the test pages

    sudo rm -f /var/www/html/about.html /var/www/html/about2.html /tmp/about2.html
    ls -lZ /var/www/html/